CVE-2025-23331

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

12 Aug 2025, 16:36

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
First Time Microsoft windows
Linux linux Kernel
Nvidia
Nvidia triton Inference Server
Microsoft
Linux
Summary
  • (es) NVIDIA Triton Inference Server para Windows y Linux contiene una vulnerabilidad que permite a un usuario asignar memoria con un tamaño excesivo, lo que provoca un fallo de segmentación, al proporcionar una solicitud no válida. Una explotación exitosa de esta vulnerabilidad podría provocar una denegación de servicio.
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23331 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23331 - Third Party Advisory
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23331 - () https://www.cve.org/CVERecord?id=CVE-2025-23331 - US Government Resource

06 Aug 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 13:15

Updated : 2025-08-12 16:36


NVD link : CVE-2025-23331

Mitre link : CVE-2025-23331

CVE.ORG link : CVE-2025-23331


JSON object : View

Products Affected

linux

  • linux_kernel

nvidia

  • triton_inference_server

microsoft

  • windows
CWE
CWE-789

Memory Allocation with Excessive Size Value